Aggregates CVE and security vulnerability intelligence across all xrdp-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Disclosed issues often relate to vendor risk buffer overflow and vendor risk input validation; exposure may include vendor impact memory corruption and vendor impact unexpected behavior in vendor surface production workloads contexts.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2008-5904 | The rdp_rdp_process_color_pointer_pdu function in rdp/rdp_rdp.c in xrdp 0.4.1 and earlier allows remote RDP servers to have an unknown impact via input data that sets crafted values for certain length variables, leading to a buffer overflow. | [email protected] | 7.5 | 7.35% | 2009-01-15 | 2026-06-16 |
| CVE-2008-5903 | Array index error in the xrdp_bitmap_def_proc function in xrdp/funcs.c in xrdp 0.4.1 and earlier allows remote attackers to execute arbitrary code via vectors that manipulate the value of the edit_pos structure member. | [email protected] | 7.5 | 3.16% | 2009-01-15 | 2026-06-16 |
| CVE-2008-5902 | Buffer overflow in the xrdp_bitmap_invalidate function in xrdp/xrdp_bitmap.c in xrdp 0.4.1 and earlier allows remote attackers to execute arbitrary code via a crafted request. | [email protected] | 7.5 | 3.38% | 2009-01-15 | 2026-06-16 |